Frames every origin that loads the WCE bundle and posts the arbitrary-JS message. A row goes FIRED only if the injected script (running in that origin) reports back. Log into the Intuit properties first to see the authenticated context. Cookie names only.